Page 2 of 2 FirstFirst 1 2
Results 11 to 19 of 19
  1. #11
    Player
    ZohnoReecho's Avatar
    Join Date
    Aug 2013
    Posts
    958
    Character
    Zohno Reecho
    World
    Ragnarok
    Main Class
    Pugilist Lv 70
    Quote Originally Posted by viion View Post
    sadly, with this game, it does jackall. It can be bypassed.
    Don't spread false info please. People are dumb enough for not using one (who can). Now we just need to promote the non use of the token.
    (2)

  2. #12
    Player
    Jwrigh7784's Avatar
    Join Date
    Jun 2011
    Location
    Gridania
    Posts
    90
    Character
    Methius Silvercloud
    World
    Behemoth
    Main Class
    Paladin Lv 90
    Quote Originally Posted by ZohnoReecho View Post
    Don't spread false info please. People are dumb enough for not using one (who can). Now we just need to promote the non use of the token.
    Actually, the authenticator can be bypassed. Someone pointed out a massive security flaw that bypasses the launcher and lets anyone log into any account and all they need is the session ID which is surprisingly easy to obtain. I have personally witnessed this and am shocked at such a security flaw.
    (1)

  3. #13
    Player
    whoopeeragon's Avatar
    Join Date
    Mar 2011
    Location
    Navigator's Glory
    Posts
    1,245
    Character
    Azarim Erro
    World
    Hyperion
    Main Class
    Lancer Lv 70
    Quote Originally Posted by Jwrigh7784 View Post
    Actually, the authenticator can be bypassed. Someone pointed out a massive security flaw that bypasses the launcher and lets anyone log into any account and all they need is the session ID which is surprisingly easy to obtain. I have personally witnessed this and am shocked at such a security flaw.
    Apparently, they have fixed it to be IP-locked now? I don't know the specifics, but people have been reporting that when they log in from a different IP, their account gets locked until they confirm it through email etc. Similar to how things worked in 1.0. For people with dynamic IPs, maybe it will be a hassle, but I think it's a welcome change. I'm not sure how this will affect session IDs, but nonetheless, it will make logins from external areas a bit harder.
    (2)

  4. #14
    Player
    ZohnoReecho's Avatar
    Join Date
    Aug 2013
    Posts
    958
    Character
    Zohno Reecho
    World
    Ragnarok
    Main Class
    Pugilist Lv 70
    Quote Originally Posted by Jwrigh7784 View Post
    Actually, the authenticator can be bypassed. Someone pointed out a massive security flaw that bypasses the launcher and lets anyone log into any account and all they need is the session ID which is surprisingly easy to obtain. I have personally witnessed this and am shocked at such a security flaw.
    If you have something that can read that session from the process believe me that nothing can stop it from redirecting the game login page to a fake one and steal the data you insert.

    Just because it can be bypassed doesn't mean you don't have to do the best to protect yourself.

    It's as if I wouldn't wear a bulletproof vest because they can shot me in the head anyway.
    (3)

  5. #15
    Player
    DragonFlyy's Avatar
    Join Date
    Sep 2013
    Posts
    889
    Character
    Jasla Angelkin
    World
    Balmung
    Main Class
    Arcanist Lv 90
    The session IDs are now being made invalid when you log off. What you are seeing is an interruption in service. If someone tried to log into your account while you are on, they get the error that someone is already logged in, it doesn't boot you out.
    (4)

  6. #16
    Player
    Join Date
    Mar 2011
    Posts
    532
    Quote Originally Posted by whoopeeragon View Post
    Apparently, they have fixed it to be IP-locked now? I don't know the specifics, but people have been reporting that when they log in from a different IP, their account gets locked until they confirm it through email etc. Similar to how things worked in 1.0. For people with dynamic IPs, maybe it will be a hassle, but I think it's a welcome change. I'm not sure how this will affect session IDs, but nonetheless, it will make logins from external areas a bit harder.
    No the IP check is because they do not have a OTP attached to the account. SE has done this for a rather long time even going back to FFXI.
    (1)

  7. #17
    Player
    Mordermi's Avatar
    Join Date
    Aug 2013
    Posts
    185
    Character
    Mordermi Auditore
    World
    Diabolos
    Main Class
    Marauder Lv 50
    (0)

  8. #18
    Player Kosmos992k's Avatar
    Join Date
    Aug 2013
    Location
    Ul'Dah
    Posts
    4,349
    Character
    Kosmos Meishou
    World
    Behemoth
    Main Class
    Paladin Lv 90
    Quote Originally Posted by Zfz View Post
    Hackers are using randomized session IDs to connect with the servers! Oh noes!


    I also got authentication error twice since last night. Either they changed something or the hackers really are doing mass brute force...
    They changed something, the chances of brute forcing a significant number of session IDs are about as high as the Sun going nova, today. It doesn't have a high enough success rate to make sense to any hacker, not to mention that it gives SE an opportunity to trace them more effectively and IP ban their sorry rear ends.
    (0)

  9. #19
    Player
    Quesse's Avatar
    Join Date
    Mar 2011
    Location
    Gridania
    Posts
    1,176
    Character
    Quesse Mithril
    World
    Sargatanas
    Main Class
    Miner Lv 70
    Quote Originally Posted by Jwrigh7784 View Post
    Actually, the authenticator can be bypassed. Someone pointed out a massive security flaw that bypasses the launcher and lets anyone log into any account and all they need is the session ID which is surprisingly easy to obtain. I have personally witnessed this and am shocked at such a security flaw.
    Sure if your computer is hacked.

    So basically if you hack someones computer, the session id becomes 'Easy to obtain'. Shocking.
    (2)

Page 2 of 2 FirstFirst 1 2